Websocket Vulnerability in GeoWebPlayer by GeoVision
CVE-2026-13125

8.8HIGH

Key Information:

Vendor
CVE Published:
2 July 2026

What is CVE-2026-13125?

GeoWebPlayer, an addon for GeoVision's software suite, has a vulnerability that allows unauthorized access to its websocket server. This lack of authentication could enable attackers to interact with sensitive API endpoints. Specifically, an attacker could exploit this vulnerability to invoke methods such as create and getScreenCapture, potentially leading to unauthorized access to a user's screen content.

Affected Version(s)

GeoWebPlayer Windows V1.1.1.0

GeoWebPlayer Windows V1.1.3.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
.